What Is the Personal Agent Protocol (PAP)? A Plain Explanation of Sierra and Meta's Standard for AI Agents and Businesses
Personal Agent Protocol explained simply: what PAP is, how guest and signed-in agent sessions work with OAuth, and who backs it: Sierra, Meta, Shopify, Stripe, Walmart.
The Personal Agent Protocol (PAP) is an open standard, announced by Sierra on October 6, 2026, that defines how a person's AI agent connects to a business and what the business lets it do. Meta is co-developing it. Genesys, Instinct, Rocket, Shopify, Stripe and Walmart are named partners. The v0.1 specification is due later in October 2026 and was not published when this was written.
The short version
Think of a personal AI agent as an assistant you send to a store on your behalf. Today, that assistant has to walk in the front door like any customer: load web pages, find buttons, fill in forms. When that fails, it ends up on a phone line or in a web chat. PAP proposes a standard side entrance, so the agent and the business can exchange what they need directly and securely.
How a PAP session works
Based on Sierra's announcement as reported by The Next Web and Unite.AI:
- Discover. The agent finds out what a company offers, starting from its website.
- Start as a guest. No login is needed for simple questions, such as whether an item is in stock or what the returns policy says.
- Customer signs in. For anything account-specific, the customer signs in and chooses whether the agent gets read-only or write access.
- Session continues. The session is built on OAuth and carries across channels, so what happened before and after sign-in stays connected.
How a business can connect
A company picks one of three routes, whichever gives the best experience:
- Its website. Agents keep using the existing site.
- An API. For example one described with MCP or OpenAPI.
- Its own agent. Useful for conversational tasks like a warranty claim.
Businesses also set limits on what agents can do, and they get visibility into when a personal agent is acting for a customer.
Is PAP a payment protocol?
No. The name is easy to confuse with the payment protocols, but PAP does not handle payments in its first version. Sierra lists payments as a future extension, alongside push notifications (for order or flight updates) and more detailed permissions.
If you want the payment side, read about x402, which lets an agent pay an HTTP endpoint. AP2 (Google's Agent Payments Protocol) is a separate effort for proving a user authorized a purchase.
What is still unknown
- The v0.1 spec text has not been published.
- No license or governing body has been named in the coverage we reviewed.
- How an agent proves which user it represents is not described.
- No production deployments have been reported.
Sierra says it will publish the spec, host design workshops and release a reference implementation. We will update this post when that happens. For a deeper comparison with MCP, AP2 and x402, see our longer piece, Personal Agent Protocol Explained.
Why it matters if you run an API or MCP server
PAP sits above your existing integrations rather than replacing them. If you already expose an MCP server or an OpenAPI description, you are on one of the three routes. The MCP Inspector shows what an agent can discover about your server today, and a clean OAuth setup is the most reusable preparation for a protocol built on it.
Follow Trango Compute on LinkedIn
We post updates on new tools, context engineering patterns, and LLM cost research.